Microsoft's own agreement — the terms every company accepts when it signs up for Microsoft 365 (formerly Office 365) — recommends, in more than one clause, that customers "regularly back up" the content they store on the service. The recommendation shows up specifically in the sections about service outages and account closures: in both cases, the text warns that Microsoft may not be able to recover what was lost.

That is not fine print buried somewhere. It is the same logic Microsoft lays out in its own technical documentation on dividing responsibility in the cloud: for any cloud service — including a ready-made application like Microsoft 365 — the provider handles the infrastructure and keeps the platform running, but the data that flows through it stays the responsibility of whoever created it. Backup, access control, and recovery sit on the customer's side, even with everything hosted in the cloud.

For whoever approves the IT budget, that distinction matters because it changes the question worth asking. It is not "is Microsoft 365 reliable" — it is. The real question is different: if an email, a folder, or a team conversation disappears by mistake, is someone keeping a copy outside the service itself, and has that copy actually been tested?

Where the cloud's guarantee ends

For any cloud service — from a rented server to a ready-made application like Microsoft 365 — Microsoft publishes a table dividing responsibility. It is clear on one point that holds across every format: company data, configurations, and user accounts remain the customer's responsibility, never Microsoft's. Not even in the ready-made application — the most "taken care of" of the three formats — does that line move.

What Microsoft does guarantee, and delivers well, is the infrastructure: data centers staying online, data replicated across different servers, the application staying available. Replication, though, is not backup — it is the same data, mirrored. If a file is deleted or corrupted, the replica gets deleted or corrupted right along with it, because its job is keeping the servers identical to each other, not keeping yesterday's version to bring back.

That is why Microsoft 365's own agreement recommends, in more than one place, that customers keep their own regular copy of what they store there — and warns that, without it, lost content may not come back.

In practice, that has a short deadline. In Exchange Online, Microsoft 365's email service, a deleted item is recoverable by default for 14 days; an administrator can extend that window, but only up to a cap of 30 days. Once that period passes, the item leaves the recovery folder for good. Thirty days is well under half the time that passed, in the opening example of this article, between the deletion and the day the director noticed.

The habit the cloud does not fix

The habit the cloud does not fix

The most common behavior here is to trust that "being in the cloud" already takes care of it — and, when the topic comes up, to treat Microsoft 365 as if it were already a backup, because files sync automatically between the computer and OneDrive or SharePoint.

Syncing has the same limit as replication: it copies the change, it does not judge whether the change was correct or a mistake. If a file is deleted, scrambled by a data-hijacking attack, or accidentally overwritten in a shared spreadsheet, syncing carries that state forward to every connected location — including the cloud.

Another common habit is leaving the topic without an owner: nobody re-reads the service agreement, nobody tests a recovery, and the first time the company learns about the retention window is exactly when it needs it — and it has already passed. At that point, the usual move is to open a ticket with Microsoft's own support and wait for a reply, with no guarantee the data still exists to be handed back.

What has to be in place

A genuinely protected Microsoft 365 environment runs on concrete mechanisms, not the assumption that "the cloud already takes care of it."

A copy kept outside Microsoft 365. Not the recycle bin or the service's own version history — an independent copy, held somewhere that stays standing even if the original account, email, or file disappears.

Coverage of every part of the environment, not just the inbox. Email, files in OneDrive and SharePoint, and what gets exchanged in Teams each have their own discard windows — the copy needs to reach all of them, not only what is most visible day to day.

A retention window longer than the service's own automatic discard period. If Microsoft 365 deletes within weeks, the independent copy needs to hold on for months — that gap is exactly what covers the case of someone noticing the mistake late.

Periodic recovery drills, not just a copy running quietly in the background: testing, from time to time, whether a specific file comes back, and how long it takes, is the only way to know the copy works before the day it actually has to.

Restoration that does not depend on opening a ticket with the manufacturer. Whoever manages the copy can hand the item back on their own, without waiting in the support queue of a provider that serves the entire world.

This is how Skills IT works: automated, encrypted copies of the Microsoft 365 environment, with a retention window set out in the contract and periodic recovery drills.

What changes in the company's day to day

What changes in the company's day to day

The first gain is the simplest to explain: an employee's mistake — deleting the wrong folder, overwriting the wrong spreadsheet — stops being a dead end. It becomes a restore request that gets resolved quickly, without rebuilding the work from memory or asking the client to resend what had already been agreed.

The second is the separation between the attack and the damage. A data-hijacking attack that scrambles files in OneDrive or SharePoint syncs that mess to the cloud right along with everything else — without a copy kept outside that cycle, there is no clean version left to recover. With one, the company goes back to a version from before the attack, instead of negotiating with whoever hijacked the files.

The third is budgetary: the cost of keeping the copy is predictable and small next to the cost of rebuilding contracts, client records, or months of lost email history — not counting the time the team spends idle while nobody knows if any of it is coming back.

Gartner projected, in August 2024, that only 15% of companies treated backup of applications used straight from the cloud — the category Microsoft 365 belongs to — as a critical priority that year, and that the share should reach 75% by 2028. In practice, that means most companies still treat the topic as something to deal with later. The bill shows up exactly when "later" arrives too late.

Four questions to bring to your next meeting

Before assuming Microsoft 365 is already covered, it is worth answering these four questions with whoever handles the company's IT:

  1. Where is the copy of the company's Microsoft 365 data, and who manages it? If the answer is "Microsoft takes care of that," it is worth re-reading the service agreement before the meeting.
  2. For how many days does a deleted email or file stay recoverable? After that window, the item leaves even the service's own recovery folder, not just the employee's computer.
  3. When was the last time anyone actually tested restoring a file? A copy that has never been tested is an assumption, not a guarantee.
  4. If someone deletes an entire folder today, who restores it, and how fast? If the answer is "open a ticket and wait," that is the point to fix first.